Zero-Fluff Technical Intelligence • Project Zero, Qualys, CTF Solutions & GitHub PoCs
Deep Exploit Writeups & Vulnerability Dossiers
Complete step-by-step root-cause breakdowns, assembly deobfuscation, memory layout maps, and verified exploit proofs-of-concept for high-impact zero-day advisories.
CVE-2024-4577
⚡ Verified PoC Code
PHP-CGI Windows Best-Fit Character Mapping Argument Injection RCE
Author: Orange Tsai • Source: DEVCORE Threat Research
Executive Summary
CVE-2024-4577 is a critical remote code execution vulnerability discovered by security researcher Orange Tsai of DEVCORE affecting PHP installations running on Microsoft Windows in CGI mode (or exposed via Apache Action application/x-httpd-php-cgi).
Assigned a...
CVE-2024-21762
⚡ Verified PoC Code
Fortinet FortiOS SSL-VPN Out-of-Bounds Write Remote Code Execution
Author: FortiGuard PSIRT Team • Source: Fortinet FortiGuard Labs
Advisory Breakdown
CVE-2024-21762 is a critical out-of-bounds write vulnerability (CWE-787) in the Fortinet FortiOS SSL-VPN web portal (sslvpnd). Assigned a CVSSv3 score of 9.8 (CRITICAL), the vulnerability allows an unauthenticated external attacker to execute arbitrary code or...
CVE-2024-1709
⚡ Verified PoC Code
ConnectWise ScreenConnect Authentication Bypass: SetupWizard Path Traversal (Deep Analysis)
Author: John Hammond & Caleb Stewart • Source: Huntress Threat Research
Executive Overview
CVE-2024-1709 is an unauthenticated, critical remote authentication bypass vulnerability affecting ConnectWise ScreenConnect (versions 23.9.7 and prior) with a maximum CVSSv3 base score of 10.0 (CRITICAL).
This vulnerability allows an unauthenticated external...
CVE-2023-38606
⚡ Verified PoC Code
Operation Triangulation: Apple iOS Kernel Zero-Day & Hardware MMIO Backdoor
Author: Boris Larin & Igor Kuznetsov • Source: Kaspersky GReAT
Threat Overview
CVE-2023-38606 is a zero-click kernel privilege escalation zero-day vulnerability utilized in the sophisticated espionage campaign known as Operation Triangulation. The vulnerability affected Apple iOS versions up to 16.5.1 and macOS versions up to 13.4.1 across ...
CVE-2024-3094
⚡ Verified PoC Code
XZ Utils Supply Chain Backdoor: Full Technical Root Cause & Deobfuscation Analysis
Author: Andres Freund & Security Research Group • Source: Kaspersky Securelist / Andres Freund
Executive Summary
In March 2024, developer Andres Freund discovered a sophisticated, multi-stage software supply chain backdoor embedded within upstream releases 5.6.0 and 5.6.1 of the xz package (specifically within liblzma). Assigned CVE-2024-3094 with a maximum CVSS score of ...